Security Basics mailing list archives

Need help on .rhosts vs hosts.eqiv


From: Nuerostar <nuerostar-basics () yahoo com>
Date: Thu, 20 Jan 2005 15:03:52 -0800 (PST)

Hi,

Does anyone know the proper issues techniques or have
good documentation/info relating to .rhosts and
hosts.equiv.  I have been googling information on it
but I haven't been able to get a concrete solid
information on these things.  

For example:  There are 3 systems A,B, and C.  Lets
just focus on hosts.equiv.  

System A and B both have themselves defined in their
hosts.equiv.  And a user John exists on both the
systems (in /etc/passwd..working account).  So John
should be able to go into A and B as himself without
typing the password as he jumps from A to B.  

And in System A there is a user called Jane.  She does
not have an account in System B.  Now can she jump to
system B? as herself or other user?  I assume she
won't be able to jump to system B am I correct? And
will the system ask for her password...even though she
does not have an account ?

For System C.  John exists in this system also, but
this system does not exist in hosts.equiv of System A
or B.  Would John be able to jump from C to A or B?  I
assume he can't ... am I right on this one?

For .rhosts

On System B - John has a .rhosts file and he allows a
user called Tom to access his home directory.  But
user Tom does not exist on System B, he only exists on
system A.  Will this scenario work or will System B
ask Tom for his password? or would it just allow it.


Any help with good info on proper workings of .rhosts
and hosts.equiv would be greatly appreciated.  


I have really searched google on this.  I got some
leads, but I would like to ask all you security gurus
on this.  I am really baffled at this.  And I
currently do not have a system(s) to try this.  

Any help is greatly appreciated.

Thanks,

nuero


Current thread: